X-Git-Url: https://plomlompom.com/repos/?p=config;a=blobdiff_plain;f=buster%2Fsetup_scripts%2Fsetup_website.sh;h=ac2d7310398179ea629ff5c2512daef96b390091;hp=035d852fc90fdbb41379825800212cc6a76b5a0e;hb=229bf1d61b7c115094a2c065ecdb9df4f04ed4dd;hpb=b631588a45593882e718395ba87701d07de64249 diff --git a/buster/setup_scripts/setup_website.sh b/buster/setup_scripts/setup_website.sh index 035d852..ac2d731 100755 --- a/buster/setup_scripts/setup_website.sh +++ b/buster/setup_scripts/setup_website.sh @@ -1,15 +1,19 @@ #!/bin/sh set -e -set -x -# Heavily inspired by -if [ "$#" -ne 3 ]; then - echo 'Need domain name and mail and old server IP as argument.' +if [ "$#" -ne 5 ]; then + echo 'Need domain name and mail and old server IP and key ID and init state (old, new?) as argument.' + false +fi +if [ ! "$5" = "old" ] && [ ! "$5" = "new" ]; then + echo "Need init state to be either 'old' or 'new'" false fi domain="$1" mail="$2" old_server="$3" +gpg_key="$4" +init_state="$5" # Install configs, set up firewall. config_tree_prefix="${HOME}/config/buster" @@ -22,43 +26,91 @@ ln -sf /etc/nginx/sites-available/default /etc/nginx/sites-enabled/default certbot --nginx --agree-tos --redirect --no-eff-email -m "${mail}" -d "${domain}" rm /etc/nginx/sites-enabled/default +# Set up connection to old server. +cp "${config_tree_prefix}/setup_scripts/prepare_to_meet_server.sh" /home/plom/ +chown plom:plom /home/plom/prepare_to_meet_server.sh +su -lc "./prepare_to_meet_server.sh ${old_server}" plom +read -p'Hit Enter when you are done.' ignore +rm /home/plom/prepare_to_meet_server.sh + # Set up repos dir. -mkdir /var/repos -chown plom:plom /var/repos # To use this dir, "git clone --mirror" repo source paths into it as user plom. # As user plom, touch git-daemon-export-ok files into it to make the repo # publically available. +if [ "${init_state}" = "new" ]; then + mkdir /var/repos + chown plom:plom /var/repos +else + cp "${config_tree_prefix}/setup_scripts/mirror_dir.sh" /home/plom/ + chmod a+w /var + su -lc "./mirror_dir.sh ${old_server} /var/repos" plom + chmod a-w /var + rm /home/plom/mirror_dir.sh +fi # Prepare NGINX and GitWeb config. sed -i "s/REPLACE_fqdn_ECALPER/${domain}/g" /etc/gitweb.conf sed -i "s/REPLACE_fqdn_ECALPER/${domain}/g" /etc/nginx/sites-available/website.nginx ln -s /etc/nginx/sites-available/website.nginx /etc/nginx/sites-enabled/website.nginx -# Set up website. +# Set up website. TODO: use non-/var/www dir for better separation to dump site rm -rf /var/www mkdir /var/www chown plom:plom /var/www -cp "${config_tree_prefix}/setup_scripts/prepare_to_meet_server.sh" /home/plom/ -chown plom:plom /home/plom/prepare_to_meet_server.sh -su -lc "./prepare_to_meet_server.sh ${old_server}" plom -read -p'Hit Enter when you are done.' ignore -su -lc "cd /var/repos && git clone --mirror ${old_server}:repos/website" plom -cp "${config_tree_prefix}/other_files/website_hook_post-receive" /var/repos/website.git/hooks/post-receive +if [ "${init_state}" = "new" ]; then + # This assumes the old core.plomlompom.com filesystem hierarchy. + su -lc "cd /var/repos && git clone --mirror ${old_server}:repos/website" plom + cp "${config_tree_prefix}/other_files/website_hook_post-receive" /var/repos/website.git/hooks/post-receive +fi su -lc 'cd /var/www && git clone /var/repos/website.git .' plom +# Add encryption key. +keyservers='sks-keyservers.net/ keys.gnupg.net' +set +e +while true; do + do_break=0 + for keyserver in $(echo "${keyservers}"); do + su plom -c "gpg --no-tty --keyserver $keyserver --recv-key ${gpg_key}" + if [ $? -eq "0" ]; then + do_break=1 + break + fi + echo "Attempt with keyserver ${keyserver} unsuccessful, trying other." + done + if [ "${do_break}" -eq "1" ]; then + break + fi +done +set -e + # Set up plomlombot. -mkdir /var/www/html/irclogs -chown plom:plom /var/www/html/irclogs -mkdir /var/www/irclogs_pw -chown plom:plom /var/www/irclogs_pw -su -lc "cd /var/repos && git clone --mirror https://plomlompom.com/repos/clone/plomlombot-irc" plom -su -lc "touch /var/repos/plomlombot-irc.git/git-daemon-export-ok" plom -cp "${config_tree_prefix}/other_files/plomlombot_hook_post-receive" /var/repos/plomlombot-irc.git/hooks/post-receive +irclogs_dir=/var/www/html/irclogs +irclogs_pw_dir=/var/www/irclogs_pw +mkdir -p "${irclogs_dir}" +chown -R plom:plom "${irclogs_dir}" +mkdir -p "${irclogs_pw_dir}" +chown -R plom:plom "${irclogs_pw_dir}" +if [ "${init_state}" = "new" ]; then + # Handle the case that the repo is in the old pre-buster server setup – + # even then, the URL should be the same. + su -lc "cd /var/repos && git clone --mirror https://plomlompom.com/repos/clone/plomlombot-irc" plom + su -lc "touch /var/repos/plomlombot-irc.git/git-daemon-export-ok" plom + cp "${config_tree_prefix}/other_files/plomlombot_hook_post-receive" /var/repos/plomlombot-irc.git/hooks/post-receive +fi su -lc "git clone /var/repos/plomlombot-irc.git" plom cp "${config_tree_prefix}/other_files/plomlombot_daemon.sh" /home/plom/ chown plom:plom /home/plom/plomlombot_daemon.sh -echo 'bot: plomlombog plomlombog #plomlomtest irc.freenode.net foo bar' >> /home/plom/.plomlombot -chown plom:plom /home/plom/.plomlombot +if [ "${init_state}" = "new" ]; then + echo 'bot: plomlombog plomlombog #plomlomtest irc.freenode.net foo bar' >> /home/plom/.plomlombot + chown plom:plom /home/plom/.plomlombot +else + cp "${config_tree_prefix}/setup_scripts/mirror_dir.sh" /home/plom/ + su -lc "./mirror_dir.sh ${old_server} /home/plom/plomlombot_db" plom + rm /home/plom/mirror_dir.sh + su -lc "scp plom@${old_server}:.plomlombot ~" plom + su -lc "ssh plom@${old_server} \"su -lc 'service plomlombot stop'\"" plom +fi + systemctl enable plomlombot.service service plomlombot start